< All Topics
Print

UPA Administration and Delegation

The delegation model in UPA enables you to configure what operations users can perform and what they can view inside of UPA. In the Administrator tab there are three nodes: Roles, Views, and Assignments.

You can use these three nodes to:

  1. Select users and assign them to the roles on the view that you have defined
  2. Define access roles, using built-in or custom roles
  3. Create a view and define the scope of permissions

Please watch this video as an overview:

We have created a pre-defined set of Roles as a starting point.  You can edit these Roles or create new Roles depending on your requirements.

The 4 Roles are:

  • Full Administrator – Administer, delegate, manage, audit the UPA system
  • Editor – Create, edit, submit policies for approval
  • Approver – Review, approve, reject, export policies
  • Reviewer – View and audit policies and history of events

The chart below shows the default Permissions for the pre-defined Roles.

Role PermissionFull AdminEditorApproverReviewer
Approve UPYesYes
AuditYesYesYesYes
Create GPOYesYes
Create New DomainYes
Create OUYesYesYes
Create UPYesYesYes
Delete ADYes
Delete DomainYes
Delete GPOYesYes
Delete OUYesYesYes
Delete UPYesYesYes
Edit Domain MapsYesYesYes
Export to ADYesYes
Import from ADYesYesYes
Modify ADYes
Modify DelegationYes
Modify GPOYesYes
Modify UPYesYesYes
Modify UP LinksYesYesYes
Rename OUYesYesYes
Rename UPYesYesYes
ReplicateYesYesYes
RollbackYesYesYes
Submit UP For ApprovalYesYesYes
Undo CheckoutYesYesYes
View ADYesYesYesYes
View DelegationYesYesYesYes
View GPOYesYesYesYes
View OUYesYesYesYes
View UPYesYesYesYes

To begin working with the pre-defined Roles, you will need to create the appropriate Users/Groups in Active Directory (or Microsoft Entra ID, etc.) and then go to Assignments and configure the Role, View, and include the appropriate Users/Groups.  See Creating and Editing Assignments for detailed instructions.

Please watch this video for an overview of how to work with the pre-configured Roles:

In This Article